rapidapi

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align, and there is no download/execute behavior. However, it sends both user query data and the RAPIDAPI_KEY through RapidAPI proxy endpoints to third-party scraper providers rather than official Google Flights or Booking.com APIs, and the referenced publisher details appear inconsistent. This is a coherent marketplace integration but carries medium trust and data-flow risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 11:26 AM
Package URL
pkg:socket/skills-sh/borski%2Ftravel-hacking-toolkit%2Frapidapi%2F@24e4c751830344eb8c2090d49294e65f3d4c875e
Security Audit — socket — rapidapi